Authentication
Identity controls, described honestly.
GlacialBooks requires a verified email address on every account and reads that verification straight from the identity-provider session before any financial-account connection flow is offered. The control is enforced server-side so it holds even when a client is modified, and we describe what we run today rather than the policy we wish we ran.
Open account securityAccount verification
Required before connecting financial accounts
Verified email address
Required
Financial account connections
Blocked until verified
Additional customer MFA
Coming soon
Verified email at signup
Every account must verify an email address before the application is usable. Verification is checked from the active identity-provider session on protected requests.
Plaid Link gate
GlacialBooks refuses to start or complete Plaid Link unless the active identity-provider session reports a verified email. The control is enforced independently of what is shown in the browser.
Critical systems
Production access to systems that store or process customer financial data requires centralized identity, scoped role assignment, and audit logging for security-relevant and accounting actions.
Support access
Internal support access is separate from customer organization roles, requires an approved internal identity, and records security-relevant activity for review.
Password and lockout controls
Password-reset links expire after 60 minutes and email-verification links expire after 24 hours. Local password accounts lock for 15 minutes after 5 failed sign-in attempts.
Additional customer MFA
Coming soon. The current financial-connection control requires a verified identity-provider email. This page will be updated when an additional customer factor is enforced.